Missing User Warnings
Medium
- Confidence
- 94% confidence
- Finding
- The skill explicitly documents raw proxy requests to an external API but does not warn that request paths, query parameters, headers, or bodies may contain sensitive user or system data that will be transmitted off-platform. In an agent setting, this increases the risk of unreviewed exfiltration of personal, organizational, or conversation-derived data to the external service.
